Stars Arena Loses Nearly Its Entire $3 Million TVL to Back-to-Back Exploits
Stars Arena, an Avalanche-based clone of FriendTech, lost almost $3 million — effectively its entire total value locked — over a single weekend, the result of two separate security failures rather than one.
The project, heavily promoted within its usual circle of backers, had already suffered a first, economically marginal exploit the day before it was fully drained. The team's own announcement of a patch — "THE EXPLOIT HAS BEEN FIXED. BUT DON'T GET THIS WRONG WE ARE AT WAR." — did little to suggest security was being taken seriously.

Team members characterized the first vulnerability as effectively "throwing money away," a framing echoed by Ava Labs CEO Emin Gün Sirer, who dismissed the incident as FUD — despite having spent the preceding week promoting the project himself. His position became harder to defend once the second hack hit, yet he doubled down anyway, arguing that the roughly $3 million loss was something the protocol "can recover... in about 10 days or so" and calling the hack "a mere speed bump." He went on to continue defending the now fully drained protocol as onlookers reacted with disbelief, prompting one observer to invoke the old advice to "stop digging."
Credit for the technical analysis goes to 0xlilitch and Beosin.
The first exploit stemmed from a broken getPrice() function, but was economically unviable in practice: draining the contract required spending roughly four times the resulting profit in gas, limiting the damage to around $2,000 before the attacker gave up — reportedly the same person who had first disclosed the bug. The team announced a fix and migrated the proxy to a new, likewise unverified, contract.
Criticism of that response was still circulating when the second exploit hit, draining $2.9 million. The replacement contract was also unverified, but Beosin's analysis found that the attacker exploited a reentrancy flaw, passing a block height value in place of the intended AVAX amount within the sellShares() function. The funds moved to address 0xa2Ebf3FCD757e9BE1E58B643b6B5077D11b4ad7A.
As scrutiny intensified, the gap between the team's stated priorities and its actual practices became apparent: despite claiming that "security is the core driving factor behind everything we do," Stars Arena reportedly retained access to users' private keys and left its infrastructure exposed to DDoS attacks — an inconsistency made harder to defend after being breached twice in as many days.

The episode fits a broader pattern: as enthusiasm for the original FriendTech model cooled over the summer, the space responded with a wave of copycat projects that added little beyond extra attack surface. FriendTech itself had separately been contending with a string of SIM-swap attacks, with accounts that performed well during the last bull run treated as priority targets, echoing an earlier pattern of easy marks. As the broader social-token model unwinds, its user base appears to be growing increasingly adversarial by the day, even as its developers have reportedly earned close to $20 million in fees since the platform's August launch.
As for Stars Arena — now widely regarded as Avalanche's latest failed promotion — the team has signaled plans for a relaunch.
Get new scam files the moment we publish them — usually 2–3 emails a week.